2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11119MEDIUM6.1A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the...
CVE-2025-11112MEDIUM6.1A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown ...
CVE-2025-11081MEDIUM5.5A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binuti...
CVE-2025-11080MEDIUM4.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects ...
CVE-2025-11073MEDIUM4.7A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an un...
CVE-2025-11069MEDIUM4.8A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this issue is some unknown functionality of the fi...
CVE-2025-11068MEDIUM4.8A vulnerability was found in westboy CicadasCMS 1.0. Affected by this vulnerability is an unknown functionality of the f...
CVE-2025-11067MEDIUM4.8A vulnerability has been found in Projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-9944MEDIUM4.3The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-9899MEDIUM6.1The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to...
CVE-2025-9898MEDIUM4.3The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2025-9896MEDIUM4.3The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3....
CVE-2025-9894MEDIUM4.3The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-9893MEDIUM4.3The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-11051MEDIUM6.5A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow...
CVE-2025-10499MEDIUM4.3The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-10498MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-8440MEDIUM6.4The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in...
CVE-2025-36239MEDIUM6.1IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u...
CVE-2025-59938MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from ...
CVE-2025-36144MEDIUM5.5IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use...
CVE-2025-57692MEDIUM6.8PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e...
CVE-2025-11034MEDIUM4.3A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function download...
CVE-2025-26258MEDIUM6.1Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'
CVE-2025-11031MEDIUM5.5A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/res...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now